Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
412 commits
Select commit Hold shift + click to select a range
5802358
chore(beads): record the sort-totality pass
Aug 30, 2026
992e839
fix(bedrock,cloudwatchlogs,lightsail,quicksight): total orderings, a …
Aug 30, 2026
9e4748e
chore(beads): export the second sort-totality record
Aug 30, 2026
a51f55a
fix(11 services): a negative continuation token panicked the request
Aug 30, 2026
b523cae
chore(beads): record the negative-token hunt
Aug 30, 2026
994cb62
fix(personalize,inspector2,translate,serverlessrepo,rolesanywhere): c…
Aug 30, 2026
68878a5
chore(beads): record the equality-cursor restart pass
Aug 30, 2026
ede6388
fix(backup): two protected-resource listings ignored pagination entirely
Aug 30, 2026
b01a02e
chore(beads): file the backup note-trust gap, record the map-walk audit
Aug 30, 2026
ccf0a6d
fix(ssm,cloudformation,eks): paginated listings with unstable ordering
Aug 30, 2026
bfd3d25
fix(macie2,pinpoint,cloudfront): tie-prone sorts over unstable sources
Aug 30, 2026
4fb5818
fix(wafv2): a marker cursor over a name that nothing keeps unique
Aug 30, 2026
911b87b
fix(elbv2,waf): ordering that a unique marker did not save
Aug 30, 2026
b900df9
fix(route53,ssoadmin,cloudwatch): orderings that two calls could disa…
Aug 30, 2026
3e29987
fix(redshift,opensearch,cognitoidp): listings whose order two calls c…
Aug 30, 2026
d0a53a2
chore(beads): correct the cognitoidp duplicate-registration count to 27
Aug 30, 2026
adb6054
chore(beads): file the autoscaling pagination gap, record the ninth o…
Aug 30, 2026
7fd7b3b
refactor(cognitoidp): delete 27 shadowed handlers, none of them reach…
Aug 30, 2026
8037934
chore(beads): close the cloudfront XML issue fixed in 9fd3308f2
Aug 30, 2026
13aec18
fix(ec2): CreateSnapshots was broken outright, and ten listings ignor…
Aug 30, 2026
8829272
fix(cloudfront,autoscaling): listings that returned everything and pr…
Aug 30, 2026
016929a
fix(ec2): CreateFleet never launched anything, so its describes had n…
Aug 30, 2026
110b839
chore(beads): close the fleet tracking issue, file ModifyFleet scaling
Aug 30, 2026
9124abd
test(rds,sns,sqs): pin the error envelope shape against the SDK deser…
Aug 30, 2026
0119faf
test(lightsail,quicksight,pinpoint,apigateway,medialive): pin error e…
Aug 30, 2026
786fa7a
fix(ec2): eight describes never read parameters the wire actually car…
Aug 30, 2026
75a3b0d
chore(beads): record the ec2 tranche and measured envelope sweep
Aug 30, 2026
bfbc46f
fix(ec2): seven more describes declared filters and never read them
Aug 30, 2026
bf34369
chore(beads): record the closing ec2 describe tranche
Aug 30, 2026
8aad0f8
fix(acmpca,ecs,xray): five error codes named types no SDK defines
Aug 30, 2026
1499dee
chore(beads): record the fabricated error code batch
Aug 30, 2026
561fa74
docs: sixteen error-code findings across five services are all false …
Aug 30, 2026
df77053
chore(beads): file the errcodeaudit false-positive classes, record th…
Aug 30, 2026
646d603
fix(appstream,opsworks): four dropped filters and a listing paginated…
Aug 30, 2026
e263119
test(apigatewayv2,apprunner,acm): all 25 paginated listings are safe …
Aug 30, 2026
2c892cc
fix(redshift): seven describes dropped filters the wire carries
Aug 30, 2026
ef0129e
chore(beads): locate the stack-instance teardown discard, file the cl…
Aug 30, 2026
426f5d3
fix(redshift): eight more describes ignored their request, completing…
Aug 30, 2026
9da77ee
chore(beads): record the completed redshift sweep
Aug 30, 2026
2879420
fix(cloudformation): a failed instance teardown no longer erases the …
Aug 30, 2026
33ef0db
chore(beads): close the stack-instance teardown issue
Aug 30, 2026
fa4b10c
fix(emr): two listings read a pagination token the wire never sends
Aug 30, 2026
e2a0429
docs: three services swept for unread request fields, one gap found
Aug 30, 2026
5864ef9
fix(sagemaker): two handlers accepted fields their operations do not …
Aug 30, 2026
40a4e0d
fix(eventbridge,iam): a versioned key that was not versioned, and thr…
Aug 30, 2026
269da5d
fix(organizations): two listings paginated over sorts that admit ties
Aug 30, 2026
7287af8
fix(cloudwatchlogs): a resource keyed by the wrong region, and three …
Aug 30, 2026
8b0dd07
chore(beads): record the cloudwatchlogs exhaustive sweep
Aug 30, 2026
0a4438b
fix(wafv2,macie2,neptune): a validator that could not reject, and two…
Aug 30, 2026
600d557
chore(beads): close the wafv2, macie2 and neptune issues
Aug 30, 2026
01b9308
chore(beads): close the autoscaling and cloudfront pagination issues …
Aug 30, 2026
33d1435
fix(memorydb): the event listing threw away its context and returned …
Aug 30, 2026
9e0e921
docs: three services checked for cross-region leaks; one collides by …
Aug 30, 2026
c523d7f
chore(beads): file the multi-region-per-process design split
Aug 30, 2026
d7cc586
fix(cloudwatch,route53): a metric-math alarm the live path never read…
Aug 30, 2026
2208016
chore(beads): close the cloudwatch CBOR and route53 VPC listing issues
Aug 30, 2026
50eaf5e
fix(iam): the entity listing read none of its filters, and hid a whol…
Aug 30, 2026
9f1ac5a
fix(enumcheck): the checker could not see a value that arrives throug…
Aug 30, 2026
a4395bf
fix(sns): two error codes named types the SDK does not define
Aug 30, 2026
b9d4fee
chore(beads): close the enumcheck struct-field issue
Aug 30, 2026
88ed7f0
fix(enumcheck,dynamodb): the checker now sees typed responses, and fo…
Aug 30, 2026
494c9f9
chore(beads): record the enumcheck typed-response extension
Aug 30, 2026
0c9b33a
fix(codebuild,elasticbeanstalk): a cascade flag never passed on, and …
Aug 30, 2026
3963c66
chore(beads): record the codebuild elasticbeanstalk batch
Aug 30, 2026
6ab03d1
fix(appsync,awsconfig,macie2,ram,redshift): seven enum values no SDK …
Aug 30, 2026
524ee6a
chore(beads): file the enumcheck confident-tier false-positive classes
Aug 30, 2026
c8ee0e2
fix(glue,opensearch): two listings that declared one parameter and ig…
Aug 30, 2026
a23dcaa
chore(beads): close the glue task-run issue, record a third PARITY st…
Aug 30, 2026
26cc5eb
fix(secretsmanager): a negation filter that matched nothing, and thre…
Aug 30, 2026
e7b0f1d
fix(enumcheck): two false-positive classes removed, confident tier fr…
Aug 30, 2026
34ecb09
fix(ssm): two filters that read their input and ignored what it meant
Aug 30, 2026
078581c
chore(beads): record the first value-semantics pass
Aug 30, 2026
c407169
fix(macie2,efs): two enum values with no legal member, and a listing …
Aug 30, 2026
4d235bf
chore(beads): file the WrapOp scanner blind spot
Aug 30, 2026
c89b314
fix(eventbridge,sns): two matchers that accept more than the real ser…
Aug 30, 2026
c79c81d
chore(beads): record fifteenth injected-footer sighting
Aug 30, 2026
6c73794
fix(securityhub): finding filters combined every entry with AND, wher…
Aug 30, 2026
56a8858
chore(beads): record the third value-semantics pass
Aug 30, 2026
aa4ec0a
fix(batch,dms,workspaces): five dropped fields in services three pass…
Aug 30, 2026
3223852
chore(beads): close the WrapOp scanner blind spot
Aug 30, 2026
8dca28d
fix(cognitoidp,ecs,rekognition): three dropped request fields, and a …
Aug 30, 2026
43ade60
fix(glue,awsconfig,workmail): six dropped or fabricated fields, found…
Aug 30, 2026
b0a7cdd
chore(beads): file the reqfieldscan dispatch-shape blind spots
Aug 30, 2026
4a58e4c
fix(emr): a session listing paginated at a fixed size whatever the ca…
Aug 30, 2026
0261a6a
chore(beads): record a self-falsifying manifest note
Aug 30, 2026
87c6544
fix(ec2): four filters that read their values and matched the wrong t…
Aug 30, 2026
bdf68bf
chore(beads): record the ec2 filter-semantics pass and sixteenth foot…
Aug 30, 2026
021efa0
fix(reqfieldscan,ce): five dispatch shapes the scanner could not see,…
Aug 30, 2026
efb0b50
chore(beads): close the scanner blind spots, file the nine newly-visi…
Aug 30, 2026
d4588f3
fix(sagemaker): a search that returned everything, and a shared time …
Aug 30, 2026
e66d953
chore(beads): record the sagemaker search pass and seventeenth footer…
Aug 30, 2026
9304cdc
fix(accessanalyzer,codecommit): nine required fields dropped, a wrong…
Aug 30, 2026
dc2121e
fix(reqfieldscan,bedrock,directoryservice,databrew): the scanner coul…
Aug 30, 2026
610c950
chore(beads): record the receiver fix and three-service scan
Aug 30, 2026
c8cee67
fix(guardduty,macie2): a page size never passed on, and two response …
Aug 30, 2026
11fb055
chore(beads): close the nine-service scan, file the seventh blind spot
Aug 30, 2026
4f70567
fix(wafv2,lakeformation): twenty-five required fields accepted, never…
Aug 30, 2026
ae25bab
chore(beads): record the wafv2 lakeformation batch
Aug 30, 2026
18399ff
fix(ce): sixty-eight unread request fields down to eight, and eight r…
Aug 30, 2026
6e48250
chore(beads): record the ce backlog retrofit
Aug 30, 2026
d2ff416
chore(beads): close the enumcheck false-positive issue
Aug 31, 2026
b9dc74b
fix(managedblockchain,xray): a required token never checked on five c…
Aug 31, 2026
c6f7981
chore(beads): record the four-small-services batch
Aug 31, 2026
5a0f0b5
fix(macie2): an oversized body returned an error code the service doe…
Aug 31, 2026
a74edf6
chore(beads): record the fourth error-code pass
Aug 31, 2026
fc17d3d
fix(lambda,backup): four filters that read their input and matched th…
Aug 31, 2026
b3ecc97
chore(beads): record the sixth value-semantics pass and first footer …
Aug 31, 2026
8163440
fix(cloudwatchlogs,ecr): a prefix applied where it should not be, and…
Aug 31, 2026
99f19e5
fix(glue): a quoted search term matched nothing, because the quotes w…
Aug 31, 2026
5c94820
chore(beads): record passes seven and eight
Aug 31, 2026
41afa3c
fix(rds): identifier filters rejected the ARN form their own document…
Aug 31, 2026
a3aa6aa
chore(beads): record the ninth value-semantics pass
Aug 31, 2026
20ac224
fix(dynamodb,pipes): a boundary documented inclusive, and two operato…
Aug 31, 2026
b563832
chore(beads): record the tenth value-semantics pass
Aug 31, 2026
9022f4b
fix(ce): an anomaly window filtered on the wrong date, and an absent …
Aug 31, 2026
51786df
chore(beads): record the eleventh value-semantics pass
Aug 31, 2026
a89bd11
fix(cloudwatch): an alarm history filter read a key no client sends, …
Aug 31, 2026
d9fd710
chore(beads): record the twelfth value-semantics pass
Aug 31, 2026
a493d2b
chore(beads): file the never-declared request field gap
Aug 31, 2026
82ce193
test(cloudformation,elbv2): both clean on filter semantics, with a re…
Aug 31, 2026
8eb4f36
chore(beads): flush the fourteenth-pass record
Aug 31, 2026
0fdecf5
fix(ecs): three defaults that widen where their documentation narrows
Aug 31, 2026
79bfb45
chore(beads): record the fifteenth pass and the wrapped-doc undercount
Aug 31, 2026
ea6fd46
fix(redshift,autoscaling,elasticache): eight filters that answered th…
Aug 31, 2026
e724a61
chore(elasticache): drop a suppression the previous commit made unnec…
Aug 31, 2026
57e06a3
chore(beads): record the sixteenth pass
Aug 31, 2026
40fb84d
fix(apprunner): a default documented true that arrives false, and a f…
Aug 31, 2026
cf988ca
chore(beads): record the seventeenth pass and the ranking correction
Aug 31, 2026
c38b737
fix(kms,servicediscovery,codecommit): a status no enum defines, an AR…
Aug 31, 2026
31de397
chore(beads): file the dashboard badge left dead by the status fix
Aug 31, 2026
9f06bd3
fix(ram): two filters reading a key the wire never sends, a dropped v…
Aug 31, 2026
6a4338b
chore(beads): record the nineteenth pass
Aug 31, 2026
f07e3dd
fix(verifiedpermissions,rekognition,cloudtrail): seven defaults lost …
Aug 31, 2026
971f896
chore(beads): record the twentieth pass
Aug 31, 2026
c75ee72
fix(codeartifact): a repository listing ignored the account filter it…
Aug 31, 2026
528144f
chore(beads): record the twenty-first pass and the heuristic failure
Aug 31, 2026
ac5c674
docs(medialive,personalize,opensearch): re-verified clean, because th…
Aug 31, 2026
0b69267
chore(beads): file the missing coverage record, record the twenty-sec…
Aug 31, 2026
45183c6
fix(quicksight): two searches dropped every filter, because this serv…
Aug 31, 2026
f3161fc
chore(beads): record the twenty-third pass
Aug 31, 2026
90970c9
feat(covledger): a ledger of which services have been audited for whi…
Aug 31, 2026
f84ae68
chore(beads): file the missing inapplicable rows, record the ledger
Aug 31, 2026
92d569c
fix(shield,iotwireless): four listings that ignored a documented defa…
Aug 31, 2026
0f7c2ed
chore(beads): record the twenty-fourth pass
Aug 31, 2026
803b46b
fix(quicksight): four listings that ignored a parameter they declare,…
Aug 31, 2026
9db7c20
chore(beads): record the twenty-fifth pass
Aug 31, 2026
ede845b
test(support,grafana): both clean, and the pass proved the new covera…
Aug 31, 2026
eb348f6
chore(beads): file the ledger's clean-verdict blind spot, record the …
Aug 31, 2026
6cae5c8
test(mediapackage,timestream,codeconnections): five services clean, a…
Aug 31, 2026
d78c750
fix(mgn): a date range decoded off the wire and then dropped, with a …
Aug 31, 2026
4ea2445
chore(beads): file the outposts aliasing finding, record the twenty-s…
Aug 31, 2026
30d6113
fix(omics): a documented default that vanished instead of appearing
Aug 31, 2026
6285fbe
chore(beads): record the twenty-eighth pass
Aug 31, 2026
559957f
test(forecast): clean after an exhaustive check, and swf was already …
Aug 31, 2026
68eacef
chore(beads): record the twenty-ninth pass
Aug 31, 2026
ee25924
test(fsx,codebuild): both clean, and the lead I sent the agent after …
Aug 31, 2026
6b5fc4c
chore(beads): record the thirtieth pass
Aug 31, 2026
77b9da3
fix(covledger): read the notes and the issue comments, because clean …
Aug 31, 2026
7328682
chore(beads): record the ledger fix and re-scope the inapplicable-row…
Aug 31, 2026
6cd895a
feat(reqfielddiff): find request fields the emulator never declared, …
Aug 31, 2026
23ff350
chore(beads): record the never-declared-field detector
Aug 31, 2026
d7149d0
fix(iot,backup,networkmanager): twenty-five operations returned an er…
Aug 31, 2026
0422f99
chore(beads): file the iot dead-code finding, record the error-envelo…
Aug 31, 2026
19f3d65
fix(bedrock): four operations returned a valid error code that their …
Aug 31, 2026
ed9c591
chore(beads): file the errcodeaudit blind spot, record the second env…
Aug 31, 2026
a24c9cd
feat(ecs,omics): declare thirty-four request fields that were never m…
Aug 31, 2026
2e5faf4
chore(beads): record the first never-declared-field sweep
Aug 31, 2026
427bd2b
fix(ec2): six listings that ignored the page size their inputs declar…
Aug 31, 2026
3c08a63
feat(errtargetaudit): find real error codes sent to operations that c…
Aug 31, 2026
cfc2bb2
chore(beads): file the query-protocol blind spot, record both landings
Aug 31, 2026
d5f8f8a
fix(reqfielddiff): count fields read from query form values, not only…
Aug 31, 2026
281784f
chore(beads): file the nondeterministic-resolution bug, record the qu…
Aug 31, 2026
3ab42ee
fix(workmail,appstream): fifty-one error emissions the receiving oper…
Aug 31, 2026
ca46f43
chore(beads): record the third class-A error sweep
Aug 31, 2026
ef0eef0
fix(tools): resolve handlers deterministically, and the collision tha…
Aug 31, 2026
103b843
chore(beads): record the determinism fix and the collision census
Aug 31, 2026
e2643a6
fix(appsync): a contact field never decoded, found by re-auditing wha…
Aug 31, 2026
3e42522
chore(beads): file the remaining collision-service re-audit, record t…
Aug 31, 2026
d488c83
fix(route53resolver,xray): thirty-two error emissions no client could…
Aug 31, 2026
139b58d
chore(beads): file the unreachable-branch false positives, record the…
Aug 31, 2026
0bc0abc
docs: fourteen services checked for handler-resolution damage, no bug…
Aug 31, 2026
9b627c7
chore(beads): record the fourteen-service collision triage
Aug 31, 2026
04455b2
fix(lambda): a function URL could be created streaming but never swit…
Aug 31, 2026
09b62a9
chore(beads): file the header-read blind spot, close out the collisio…
Aug 31, 2026
43416bb
fix(cloudwatchlogs,cloudformation): twenty-four error emissions no cl…
Aug 31, 2026
7e5c9bd
chore(beads): file the sentinel-table collision, record the fifth err…
Aug 31, 2026
4daec00
fix(reqfielddiff): stop counting a response struct's members as reque…
Aug 31, 2026
c861e2e
chore(beads): record the suppressed-findings fix
Aug 31, 2026
e2a4d08
fix(rds): six restore and replica inputs ignored parameter and option…
Aug 31, 2026
8d6b4c9
chore(beads): record the newly-surfaced field validation
Aug 31, 2026
218dc93
docs(autoscaling,elb,elasticache,ses): response element naming re-ver…
Aug 31, 2026
3e3c66d
chore(beads): record the response-naming re-verification and correct …
Aug 31, 2026
9c4a926
test(backup,mgn,s3control): typed round-trip coverage for nested list…
Aug 31, 2026
e4c2e45
docs(mgn): correct the caveat on the round-trip tests, which was wron…
Aug 31, 2026
ab370fd
chore(beads): record the failability proof and the case-folding corre…
Aug 31, 2026
895a2c3
docs(sns,elasticbeanstalk): exact-case element check clean, and only …
Aug 31, 2026
b94b4c7
chore(beads): record the exact-case check and the protocol correction
Aug 31, 2026
11b8317
fix(iam,cloudfront): list items missing fields the client reads, incl…
Aug 31, 2026
c954441
chore(beads): record the XML exact-case sweep
Aug 31, 2026
e480578
fix(cloudfront,iam): nine listings whose items dropped fields their s…
Aug 31, 2026
2ee5cf1
chore(beads): file the ARN truncation, record the XML continuation
Aug 31, 2026
404f8d8
fix(iam,route53): two listings that dropped fields their own siblings…
Aug 31, 2026
3e995ff
fix(errtargetaudit): scope the sentinel table per mapper, and drop wh…
Aug 31, 2026
e076afb
docs: regenerate service READMEs and the operations badge
Aug 31, 2026
4af31e0
ci: give the unit-test job full history, which its own tests require
Aug 31, 2026
40a2fae
fix(persistence): bump seven snapshot versions where an old snapshot …
Aug 31, 2026
29bcbda
chore(beads): file the opensearch unpersisted-deadline bug
Aug 31, 2026
4917304
chore(beads): file the kinesis event-stream flake
Aug 31, 2026
ee27092
fix(test): repair two integration tests, one broken by this branch an…
Aug 31, 2026
12e3ff4
fix(neptune,s3control): a port that only existed nested, and two list…
Aug 31, 2026
ca4dedf
chore(beads): record the s3control/neptune element-naming sweep
Aug 31, 2026
6839d14
fix(ec2): thirteen request fields that were never modelled, and eight…
Aug 31, 2026
42dee4a
chore(beads): record the ec2 never-declared-field sweep
Aug 31, 2026
c7f8984
fix(cloudformation): a stack-instance element the client never reads,…
Aug 31, 2026
79cdfa1
chore(beads): file the nested-stack parent bug, record the cloudforma…
Aug 31, 2026
3f7597a
fix(ec2): a tag deletion that deleted nothing, a tenancy never render…
Aug 31, 2026
53fc055
chore(beads): record the ec2 continuation
Aug 31, 2026
b5e09ec
fix(cloudformation): a listing that returned nothing to any client, a…
Aug 31, 2026
cefd4a1
chore(beads): record the cloudformation wrapper-key regression class
Aug 31, 2026
2dc4bfa
fix(rds,medialive,comprehend): two transposed wire tags, three list i…
Aug 31, 2026
0322fc3
chore(beads): record the PARITY-gap targeting batch
Aug 31, 2026
c2b2c61
fix(sagemaker): two listings dropping fields their own describe emits…
Aug 31, 2026
d02b0c6
fix(cleanrooms): four list summaries dropping fields their own get al…
Aug 31, 2026
ee7f2cc
chore(beads): file the wire/persistence struct conflation
Aug 31, 2026
5a41372
fix(backup): a status emitted under a name its type does not have, an…
Aug 31, 2026
27992e8
chore(beads): record PARITY-gap batches two through four
Aug 31, 2026
51ef6c4
fix(dynamodb): an import compression the backend recorded and never r…
Aug 31, 2026
d676cf5
fix(cloudfront,athena): five findings, including a field carrying the…
Aug 31, 2026
b46a091
chore(beads): record the targeting false-positive mode and the wrong-…
Aug 31, 2026
a1d8140
fix(lambda,opensearch,transfer): six findings, none of them in the op…
Aug 31, 2026
5cdbf61
chore(beads): record the final PARITY-gap batch and the method's hone…
Aug 31, 2026
9cf2d22
fix(fsx,codestarconnections): fourteen error emissions no client coul…
Aug 31, 2026
3630e7f
chore(beads): record the sixth class-A error sweep
Aug 31, 2026
ffb4ce7
fix(eventbridge,pinpoint,textract): fifteen error emissions no client…
Aug 31, 2026
773bfa8
fix(errtargetaudit): suppress findings whose emitting branch the oper…
Aug 31, 2026
c31c058
chore(beads): record the reachability fix and the seventh error sweep
Aug 31, 2026
8c0cfeb
docs: regenerate READMEs after this round's PARITY edits
Aug 31, 2026
290af78
Merge branch 'main' into fix/wrapper-key-sweep-rds-cloudwatch-sqs-sns
agbishop Aug 31, 2026
6805b35
fix: address PR review, including an unescaped error body and two fin…
Aug 31, 2026
579327d
fix(iot): six creations reporting an already-exists code their operat…
Aug 31, 2026
05493b2
chore(beads): record the seventh class-A sweep
Aug 31, 2026
75a95f6
fix(sns,codeconnections): five error emissions no client could decode…
Aug 31, 2026
6434a8a
chore(beads): file the discarded-error tagging bug
Aug 31, 2026
fb1b443
fix(ses,kinesisanalytics): seven undeclared error emissions, every on…
Sep 1, 2026
f5a8f0b
chore(beads): record ec2 clean for the wrapper-key class
Sep 1, 2026
60f6d11
chore(beads): record four services clean and retire a fifth failed he…
Sep 1, 2026
4c7e060
chore(beads): record cloudfront and docdb clean, file two adjacent cl…
Sep 1, 2026
6e62b09
fix: address codeql, codefactor complexity, and wire field fixes
Sep 1, 2026
5a38ec7
fix(cloudfront): use application/xml Content-Type to resolve CodeQL X…
Sep 1, 2026
3ecd1da
fix(cloudfront): route xml responses through c.Blob
Sep 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
6 changes: 3 additions & 3 deletions .badges/operations.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
367 changes: 225 additions & 142 deletions .beads/issues.jsonl

Large diffs are not rendered by default.

3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -193,9 +193,12 @@ jobs:
matrix:
chunk: [0, 1, 2, 3]
steps:
# Full history: cmd/errcodeaudit's tests materialize services/ecs at an
# old revision with `git archive`, which a shallow clone cannot resolve.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
token: ${{ env.GH_CI_TOKEN }}
fetch-depth: 0

- name: Free Disk Space (Ubuntu)
uses: jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be # main
Expand Down
9 changes: 9 additions & 0 deletions .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -502,6 +502,12 @@ linters:
# injectable RNG field, so it must live in the same package.
- path: 'route53/routing_test.go'
linters: [ testpackage ]
# handler_error_xml_test.go white-box tests the unexported cfErrorXML
# directly, since driving the escaping bug through a real HTTP round
# trip would require reverse-engineering a reachable injection point
# into the dispatcher's `operation` string.
- path: 'cloudfront/handler_error_xml_test.go'
linters: [ testpackage ]
# ordering_requirements_test.go white-box tests buildOrderingRequirements
# and its unexported per-check helpers directly with hand-built Site/
# Outpost structs -- several of the real OrderingRequirementType checks
Expand Down Expand Up @@ -536,6 +542,9 @@ linters:
linters: [ staticcheck ]
- path: 'opsworks/sdk_roundtrip_helper_test.go'
linters: [ staticcheck ]
# Same reasoning as opsworks/sdk_roundtrip_test.go above.
- path: 'opsworks/list_filter_params_test.go'
linters: [ staticcheck ]
- path: 'pkgs/service/cloudtrail_capture_test.go'
linters: [ testpackage ]
- path: 'pkgs/service/registry_test.go'
Expand Down
102 changes: 51 additions & 51 deletions README.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion cli_asg_ec2_wiring_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ func TestWireAutoScalingEC2_ScaleOutCreatesRealEC2Instance(t *testing.T) {
// --- Scale-in: reducing DesiredCapacity must terminate the removed instance in EC2 too. ---
require.NoError(t, asgBk.SetDesiredCapacity("wiring-test-asg", 1))

groups, err := asgBk.DescribeAutoScalingGroups([]string{"wiring-test-asg"})
groups, err := asgBk.DescribeAutoScalingGroups([]string{"wiring-test-asg"}, nil)
require.NoError(t, err)
require.Len(t, groups, 1)
require.Len(t, groups[0].Instances, 1)
Expand Down
2 changes: 1 addition & 1 deletion cli_elb_ec2_acm_wiring_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ func TestInitializeServices_ELBEC2ACMWiring(t *testing.T) {

ctx := t.Context()

vpc, err := ec2H.Backend.CreateVpc("10.0.0.0/16")
vpc, err := ec2H.Backend.CreateVpc("10.0.0.0/16", "default")
require.NoError(t, err)

sg, err := ec2H.Backend.CreateSecurityGroup("wiring-test-sg", "wiring test", vpc.ID)
Expand Down
6 changes: 3 additions & 3 deletions cli_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -848,7 +848,7 @@ func TestWireResourceGroupsTagging_CrossServiceResources(t *testing.T) {

batchBk := batchbackend.NewInMemoryBackend(accountID, region)
ce, err := batchBk.CreateComputeEnvironment(
context.Background(), "wiring-test-ce", "UNMANAGED", "ENABLED", nil, "", nil, nil, nil,
context.Background(), "wiring-test-ce", "UNMANAGED", "ENABLED", nil, "", nil, nil, nil, nil,
)
require.NoError(t, err)
require.NoError(t, batchBk.TagResource(
Expand Down Expand Up @@ -1373,7 +1373,7 @@ func TestWireResourceGroupsTagging_CrossServiceResources(t *testing.T) {

ceBk := cebackend.NewInMemoryBackend(accountID, region)
cat, err := ceBk.CreateCostCategoryDefinition(
"wiring-test-cat", "CostCategoryExpression.v1", "", nil, nil,
"wiring-test-cat", "CostCategoryExpression.v1", "", nil, nil, nil, "",
)
require.NoError(t, err)
require.NoError(t, ceBk.TagResource(cat.ARN, map[string]string{wantTagKey: wantTagValue}))
Expand Down Expand Up @@ -2298,7 +2298,7 @@ func TestWireResourceGroupsTagging_TagResourcesRoundTrip(t *testing.T) {

batchBk := batchbackend.NewInMemoryBackend(accountID, region)
ce, err := batchBk.CreateComputeEnvironment(
context.Background(), "roundtrip-ce", "UNMANAGED", "ENABLED", nil, "", nil, nil, nil,
context.Background(), "roundtrip-ce", "UNMANAGED", "ENABLED", nil, "", nil, nil, nil, nil,
)
require.NoError(t, err)

Expand Down
252 changes: 252 additions & 0 deletions cmd/acceptguard/main.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,252 @@
// Command acceptguard finds gopherstack handlers that accept a REQUEST
// member the real pinned aws-sdk-go-v2 Input type does not declare -- the
// mirror image of every wire bug this campaign has found so far, which were
// all on the response side (a member emitted under the wrong key, dropped,
// or invented). networkmanager's ListAttachments/ListPeerings EdgeLocation
// filter was the case that first surfaced this direction (gopherstack-6flj);
// see this package's doc comment continuation in scan.go and this tool's own
// test file for why that specific historical commit (5591e3014) turned out,
// on structural inspection, NOT to be an instance of this class after all --
// an important calibration finding in its own right, not a tool bug.
//
// GROUND TRUTH, not a naming guess, reusing cmd/enumcheck's and
// cmd/zeroguard's own per-service SDK module resolution (modresolve.go,
// copied verbatim) and go/ast struct parsing (sdkfields.go):
//
// - A gopherstack top-level struct whose name ends in one of
// requestSuffixes (Input/Request/Params/Req) is a candidate "what this
// handler accepts" shape. Stripping the suffix and capitalizing the
// first rune proposes a real AWS operation name (createVpcAttachmentReq
// -> CreateVpcAttachment).
// - That candidate is verified, not assumed: it only proceeds if the
// pinned SDK module actually declares api_op_<Op>.go with an
// <Op>Input struct (sdkfields.go's fieldsFor).
// - Every one of the candidate struct's own top-level fields is compared,
// case/abbreviation-folded (zeroguard's matchSDKField precedent), against
// that real Input's field set. A field present there is fine and
// produces nothing.
// - A field ABSENT from the target op's real Input is only reported once
// REACHABILITY is confirmed structurally: some function in the package
// binds a local identifier to the struct's type (a parameter or `var`
// declaration) and reads `<that identifier>.<field>` somewhere in its
// body. A decoded-but-never-read field is this repo's documented
// non-bug (an emulator-internal hook unreachable from the real wire
// path) and is silently skipped, not reported at either confidence
// level.
// - CONFIDENT (kindInvented): the field's name (folded) matches NO member
// of ANY real Input struct anywhere in the resolved SDK module -- not
// just absent from this op, absent from the entire service's real
// surface. Invented wholesale.
// - NEEDS REVIEW (kindSibling): the field's name IS a real member, just of
// a different operation's Input in the same module -- the repo's other
// documented non-bug (a field that lives on a sibling or Create/Update-
// paired Input) made concrete and worth a human's look rather than
// silently dropped, since the field could genuinely be wired to the
// wrong op.
//
// PROTOCOL SCOPE, disclosed rather than silently under-covered: this signal
// only sees a REQUEST shape gopherstack represents as a genuine Go struct
// with named fields -- every JSON-family service this repo has (a decoded
// body, or an apigatewayv2-style hand-populated params struct) qualifies.
// Query and ec2-query services pull request members out of url.Values by
// literal key (`vals.Get("SomeParam")`) with no struct to enumerate fields
// from at all, and REST-XML services with flattened/indexed member names
// (Filters.Filter.1.Name) would need a wire-key grammar this tool does not
// implement -- both protocol families see zero candidates and zero
// findings, not a false "clean" verdict for a different reason: there was
// never a struct here for this tool to examine in the first place.
//
// SCOPE, disclosed rather than silently under-covered: only files directly
// in services/<dir> are scanned for candidate structs and their usage (no
// recursion into subpackages, no _test.go files); only a struct's own
// TOP-LEVEL fields are checked -- a mismatch nested inside a pointer-to-
// struct member (e.g. Options *vpcOptionsWire) is a different shape and out
// of this tool's signal entirely, matching zeroguard's own disclosed nested-
// struct exclusion.
//
// Usage:
//
// go run ./cmd/acceptguard # report to stdout
// go run ./cmd/acceptguard -json out.json # also write full finding list as JSON
//
// Exit codes: 0 no confident findings (needs-review hits may still print),
// 1 a run error, 2 at least one confident finding.
package main

import (
"flag"
"fmt"
"os"
"path/filepath"
"sort"
)

const (
exitClean = 0
exitRunError = 1
exitConfidence = 2
)

// sdkModule is one resolved aws-sdk-go-v2/service/<name> module a
// services/<dir> package imports, with its on-disk GOMODCACHE path at the
// version pinned in go.mod.
type sdkModule struct {
name string
path string
}

func main() {
jsonOut := flag.String("json", "", "write the full finding list to this path as JSON")
flag.Parse()

findings, err := run()
if err != nil {
fmt.Fprintln(os.Stderr, "error:", err)
os.Exit(exitRunError)
}

if *jsonOut != "" {
if werr := writeJSON(*jsonOut, findings); werr != nil {
fmt.Fprintln(os.Stderr, "write json:", werr)
os.Exit(exitRunError)
}
}

printReport(findings)
os.Exit(exitCode(findings))
}

func run() ([]finding, error) {
repoRoot, err := repoRootDir()
if err != nil {
return nil, err
}

cache, err := gomodcacheDir(repoRoot)
if err != nil {
return nil, err
}

goModVersions, err := loadGoModVersions(filepath.Join(repoRoot, "go.mod"))
if err != nil {
return nil, err
}

svcDirs, err := serviceDirs(filepath.Join(repoRoot, "services"))
if err != nil {
return nil, err
}

fieldCache := newSDKFieldCache()

var all []finding

for _, dir := range svcDirs {
found, scanErr := auditServiceDir(dir, repoRoot, cache, goModVersions, fieldCache)
if scanErr != nil {
return nil, fmt.Errorf("%s: %w", dir, scanErr)
}

all = append(all, found...)
}

sort.Slice(all, func(i, j int) bool {
if all[i].File != all[j].File {
return all[i].File < all[j].File
}

return all[i].Line < all[j].Line
})

return all, nil
}

func serviceDirs(svcRoot string) ([]string, error) {
entries, err := os.ReadDir(svcRoot)
if err != nil {
return nil, err
}

var dirs []string

for _, e := range entries {
if !e.IsDir() {
continue
}

dirs = append(dirs, filepath.Join(svcRoot, e.Name()))
}

sort.Strings(dirs)

return dirs, nil
}

// auditServiceDir resolves every aws-sdk-go-v2 module dir's own files
// import (test files included -- resolveServiceModules's own doc comment)
// and scans dir against each resolved module's own pinned Input ground
// truth. A service with no resolvable SDK module contributes nothing --
// never an error.
func auditServiceDir(
dir, repoRoot, cache string, goModVersions map[string]string, fieldCache *sdkFieldCache,
) ([]finding, error) {
names, err := resolveServiceModules(dir)
if err != nil {
return nil, err
}

var mods []sdkModule

for _, name := range names {
ver, ok := goModVersions[name]
if !ok {
continue
}

modPath := filepath.Join(cache, "github.com", "aws", "aws-sdk-go-v2", "service", name+"@"+ver)
mods = append(mods, sdkModule{name: name, path: modPath})
}

if len(mods) == 0 {
return nil, nil
}

preferOwnModule(mods, filepath.Base(dir))

return scanPackage(dir, repoRoot, mods, fieldCache)
}

// preferOwnModule reorders mods in place so the module named for the
// service's own directory (dax/handler.go imports dax's own SDK for its
// round-trip tests, matching every service here) sorts first -- ahead of
// any OTHER aws-sdk-go-v2 module a package's test files import for cross-
// service validation (dax's own dataplane_integration_test.go imports
// dynamodb; networkmanager's crossservice.go pattern has services import
// each other's real backends too). Without this, resolveOpFields's
// first-match-wins search over mods could resolve an operation name TWO
// unrelated services both happen to define (TagResource/UntagResource are
// nearly universal) against the WRONG service's Input shape entirely --
// confirmed live: dax's own TagResourceInput/UntagResourceInput both
// declare ResourceName correctly, but dynamodb's own TagResourceInput uses
// ResourceArn, and alphabetical file iteration resolved dax's module
// import after dynamodb's, producing a false CONFIDENT finding on a field
// that was never wrong.
func preferOwnModule(mods []sdkModule, dirName string) {
for i, m := range mods {
if m.name == dirName {
mods[0], mods[i] = mods[i], mods[0]

return
}
}
}

func exitCode(findings []finding) int {
for _, f := range findings {
if f.Confident {
return exitConfidence
}
}

return exitClean
}
Loading
Loading